7.5
CVSSv2

CVE-2021-3849

Published: 22/04/2022 Updated: 27/10/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An authentication bypass vulnerability exists in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated malicious user to execute commands on the SMM and FPC2. SMM2 is not affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lenovo nextscale n1200 enclosure firmware

lenovo thinkagile hx enclosure certified node firmware

lenovo thinkagile vx enclosure firmware

lenovo thinksystem d2 enclosure firmware

ibm nextscale fan power controller firmware